GHSA-rv4h-m4wc-v99w
Dashboard / Vulnerabilities / GHSA-rv4h-m4wc-v99w
Summary: Apache Archiva Incorrect Authorization vulnerability
Details: ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting to disable user registration, however this restriction can be bypassed. As Apache Archiva has been retired, we do not expect to release a version of Apache Archiva that fixes this issue. You are recommended to look into migrating to a different solution, or isolate your instance from any untrusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
References: https://nvd.nist.gov/vuln/detail/CVE-2024-27138, https://github.com/apache/archiva, https://lists.apache.org/thread/070qcpclcb3sqk1hn8j5lvzohp30k1m2, http://www.openwall.com/lists/oss-security/2024/03/01/4
Affected packages
Package
Name: org.apache.archiva:archiva
Purl: pkg:maven/org.apache.archiva/archiva
Affected ranges
Type: ECOSYSTEM
Events:
